Threat reportMalwareTL-2026-1533
Lumma Infostealer (LummaC2): MaaS Credential Theft via NSIS/AutoIt/ClickFix Evasion Chain
Lumma Infostealer (LummaC2) (TL-2026-1533), also tracked as LummaC2, is a high-severity malware campaign, first published 2026-07-19. It is attributed to Shamel (Russia) with medium confidence, affects Microsoft Windows (all supported desktop versions), maps to 29 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1Shamel
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-1533
- Threat ID
- TL-2026-1533
- Also known as
- LummaC2, Lumma Stealer, Trojan:Win32/LummaStealer
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Shamel
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, criticalinfrastructure, gaming, education, cryptocurrency, generalenterprise
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Lumma Infostealer (LummaC2)
Malware and tooling: Lumma Stealer / LummaC2, renamed 7-Zip binary
How Lumma Infostealer (LummaC2) works
Lumma Stealer (LummaC2) is a Russian-developed, subscription-based Malware-as-a-Service infostealer active since August 2022 that ranked #1 in ANY.RUN's malware detection statistics as of September 2025. It uses NSIS packaging, obfuscated AutoIt scripts, shellcode injection, and process hollowing to exfiltrate browser credentials, cryptocurrency wallets, Telegram sessions, and VPN/RDP data, and survived a May 2025 Microsoft/DOJ/Europol domain-seizure operation before rebounding within days and evolving into a Windows Terminal-based ClickFix delivery chain disclosed by Microsoft in March 2026.
Lumma Stealer, tracked by the security community as LummaC2, first appeared for sale on Russian-language cybercriminal forums in 2022 and is attributed to a threat actor operating under the alias "Shamel." It is offered as a tiered Malware-as-a-Service subscription (documented pricing from roughly $140/month for a standard build up to $20,000 for a source-code license enabling resale), marketed and supported through Telegram channels with 1,800+ members.
The malware's most recent documented distribution chain (Genians, October 2025) begins with phishing sites disguised as pirated/cracked software. Victims are redirected through multiple intermediary sites to obscure the origin, with the final payload staged on MEGA cloud storage. The downloaded Setup.exe is an NSIS (Nullsoft Scriptable Install System) installer that drops files into %Temp%, opens a decoy document ("Contribute.docx") to distract the victim, and invokes the native Windows utility extrac32.exe to extract a CAB archive disguised as "Make.docx," which actually contains 11 component files including a fragmented, ASCII-obfuscated AutoIt3.exe runtime and a heavily obfuscated compiled AutoIt script full of dummy/junk code. The AutoIt script reassembles the fragmented interpreter, decrypts embedded shellcode, and performs process hollowing/injection into a process that displays as an innocuous file named "Riding.pif" while actually executing the Lumma payload in memory — evading static and process-name-based detections. Before execution, the malware enumerates running processes to detect and evade security products including Sophos, Norton, ESET, and Bitdefender.
Lumma is written in C++ and assembly and targets Chromium-, Mozilla-, and Gecko-based browsers, harvesting session cookies, autofill data, saved passwords, cryptocurrency wallet keys/extensions, Telegram session data, email/FTP/VPN/RDP client credentials, and user documents. Exfiltration occurs over HTTP POST to attacker C2 infrastructure that fronts real backend servers behind proxy layers; C2-delivered configuration files control which browsers/wallets/apps are targeted per victim.
Beyond the phishing/cracked-software vector, Lumma affiliates independently distribute the stealer via malvertising (poisoned search results impersonating legitimate brands), compromised websites injecting malicious JavaScript, GitHub repository social-engineering campaigns (fake tool/cheat repos), and — most prominently — ClickFix / fake-CAPTCHA social engineering, where victims are instructed to press Win+R and paste an attacker-supplied command that downloads and runs the stealer via PowerShell, mshta, or a non-resident EXE/DLL loader.
In May 2025, the FBI and CISA issued joint advisory AA25-141B documenting LummaC2 TTPs and IOCs spanning infections from November 2023 through May 2025, coinciding with a coordinated takedown led by Microsoft's Digital Crimes Unit alongside the US DOJ, Europol, and Japan's Cybercrime Control Center that disrupted approximately 2,300 malicious domains (1,300+ seized or transferred to Microsoft) and targeted the central command-and-control panel infrastructure. LummaC2 operators publicly acknowledged the disruption to their Telegram customer base and stood up replacement domains within 24-48 hours; the government seized those replacement domains as well within days, but the operation ultimately only delayed rather than eliminated the service, and Lumma resumed high-volume operation within weeks.
Most recently, Microsoft Threat Intelligence disclosed (March 5, 2026) a new ClickFix variant observed in campaigns from February 2026 that abandons the traditional Win+R Run-dialog lure — which many EDR products now alert on via process-parentage rules — in favor of instructing victims to open Windows Terminal directly (Win+X, then "I"). This blends malicious command execution into what appears to be a legitimate administrative workflow and defeats detection logic keyed to Run-dialog ancestry. The Windows Terminal session spawns additional PowerShell/Terminal instances that retrieve a ZIP payload alongside a renamed 7-Zip binary, extract further payloads, establish scheduled-task persistence, add Microsoft Defender exclusions for the malware's working directories, exfiltrate host/network reconnaissance data, and finally deploy Lumma Stealer proper. This demonstrates continued rapid TTP evolution specifically engineered to outpace defensive telemetry built around earlier ClickFix indicators.
MITRE ATT&CK techniques used in TL-2026-1533
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
Privilege Escalation
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
stealth
T1218 System Binary Proxy Execution
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
defense-impairment
Affected products and versions in Lumma Infostealer (LummaC2)
- Microsoft — Windows (all supported desktop versions)
Vulnerable versions: Windows 10; Windows 11
Remediation for Lumma Infostealer (LummaC2)
Immediate actions
- Block the documented C2 domains and IPs (rhussois[.]su, diadtuky[.]su, todoexy[.]su and associated infrastructure) at DNS/firewall/proxy layer
- Block or restrict extrac32.exe execution from user-writable temp directories via application control / AppLocker
- Force browser credential re-authentication and rotate any session cookies/passwords on hosts with confirmed Lumma execution
- Revoke and rotate cryptocurrency wallet keys and API credentials on any affected endpoint
Workarounds
- Disable or restrict clipboard-to-Run-dialog and clipboard-to-Terminal paste execution via GPO where feasible
- Enforce application allowlisting to block AutoIt3.exe execution from non-standard install paths
Longer-term hardening
- Deploy EDR/behavioral detection tuned to process hollowing and shellcode injection into legitimate-looking processes, not just Run-dialog ancestry
- Add detection coverage for Windows Terminal (wt.exe)-initiated PowerShell chains, not only cmd.exe/mshta/Run-dialog lineage, to catch the March 2026 ClickFix evolution
- Monitor for unauthorized Microsoft Defender exclusion additions as a persistence/evasion indicator
- User awareness training against ClickFix/fake-CAPTCHA social engineering and cracked-software phishing lures
- Restrict use of NSIS-packaged unsigned installers and cracked-software downloads via web/DNS filtering
Timeline of Lumma Infostealer (LummaC2)
- Lumma Stealer first appears for sale on Russian-language cybercriminal forums under the alias 'Shamel', offered as a subscription-based Malware-as-a-Service.
- US government seizes two core LummaC2 command-and-control domains as part of a coordinated Microsoft/DOJ/Europol/Japan Cybercrime Control Center takedown operation.
- LummaC2 administrators notify their Telegram customer base of three newly stood-up replacement domains for the user panel.
- Government seizes the three replacement domains; FBI and CISA jointly publish advisory AA25-141B documenting LummaC2 TTPs and IOCs covering infections from November 2023 through May 2025; Microsoft publishes technical breakdown of Lumma delivery techniques.
- Lumma Stealer operations resume at high volume within weeks of the takedown, rebuilding C2 infrastructure and continuing MaaS sales.
- Lumma Stealer ranks #1 in ANY.RUN's malware detection statistics as of September 2025, reflecting its status as the most widely detected infostealer in the wild.
- Genians Threat Intelligence publishes detailed analysis of the NSIS/AutoIt/process-hollowing distribution chain, including confirmed C2 domains, IPs, and file hashes from active campaigns.
- Microsoft observes a new ClickFix campaign variant abusing Windows Terminal (Win+X, then 'I') instead of the Run dialog to deliver Lumma Stealer, evading EDR rules tuned to Run-dialog process ancestry.
- Microsoft Threat Intelligence publicly discloses the Windows Terminal-based ClickFix delivery chain, detailing the multi-stage PowerShell/7-Zip payload retrieval, scheduled-task persistence, and Defender-exclusion evasion steps.
Sources cited for Lumma Infostealer (LummaC2)
- Analysis of the Lumma infostealer
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations (AA25-141B)
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
- Threat Actors Target U.S. Critical Infrastructure with LummaC2 Malware
- Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer
- Disrupting Lumma Stealer Malware – Microsoft Leads Global Action
- Lumma infostealer's infrastructure seized during US, EU, Microsoft operation
- Microsoft leads international takedown of Lumma Stealer
- Advisory Alert: Lumma Stealer Rebounds After Takedown
- Lumma Malware: Unmasking the Stealthy Infostealer
- Lumma Stealer: A fast-growing infostealer threat
- How Lumma Stealer sneaks into organizations
- Lumma Infostealer Data Exfiltration Campaign Continues on a Large Scale
- LummaC2 infostealer | Malware infection records skyrocket 2000%
- Trojan:Win32/LummaStealer threat description
Detection coverage for TL-2026-1533
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1533 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1533
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.